PT-2026-50740 · Zitadel · Zitadel
CVE-2026-55671
·
Published
2026-06-18
·
Updated
2026-07-30
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Zitadel versions 4.0.0 through 4.15.1
Zitadel versions 3.0.0 through 3.4.11
Description
A Server-Side Request Forgery (SSRF) issue exists in components that handle outgoing HTTP requests, specifically HTTP Notification Channels, OIDC BackChannel Logout, and SAML Metadata URL Fetches. User-defined URLs were not properly validated against an internal denylist, allowing attackers to provide arbitrary URLs such as loopback addresses, internal IPs, or cloud link-local addresses. This could enable internal network mapping, port scanning, or interaction with unauthorized internal services. The denylist mechanism was also susceptible to DNS rebinding (a technique to bypass DNS-level security checks by changing the IP address associated with a domain name between the time of validation and the time of use), HTTP redirects, and protocol downgrades from HTTPS to HTTP. In cloud environments, this could potentially be used to target unauthenticated cloud metadata endpoints like
169.254.169.254.Recommendations
Upgrade Zitadel versions 4.0.0 through 4.15.1 to version 4.15.2 or later.
Upgrade Zitadel versions 3.0.0 through 3.4.11 to version 4.15.2 or later.
Implement strict network policies, egress firewalls, or reverse proxy rules to block outbound connections from Zitadel to internal networks, loopback interfaces, or cloud metadata endpoints.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zitadel